An AI system may demonstrate strong technical performance while simultaneously creating risks for customers, employees or the business. For example, a credit scoring system may speed up application processing while rejecting applicants from a particular group more frequently. This is why it is important to assess not only the model’s accuracy, but also the consequences of its use.
ISO/IEC 42005:2025 provides an approach for assessing the impact of an AI system on individuals, groups and society. ISO/IEC 42001 helps organisations establish an artificial intelligence management system and manage AI at an organisational level.
ISO/IEC 42005 and ISO/IEC 42001: What Is the Difference
ISO/IEC 42005 helps assess a specific AI system: identify who may be affected, determine potential positive and negative impacts, evaluate their significance, and define the necessary control measures.
ISO/IEC 42001 sets requirements for roles, responsibilities, risks, controls, monitoring and continual improvement. Put simply, ISO/IEC 42005 answers the question, “What impact could this system have?”, while ISO 42001 addresses, “How will the organisation manage that impact systematically?”
How to Conduct an AI System Impact Assessment
The assessment should be carried out before deployment and then repeated whenever there are significant changes to the model, data or intended purpose. This is particularly important for banking, fintech, healthcare, public services, telecommunications and e-commerce, where an algorithm may affect finances, health, rights or access to services.
A practical process can be structured as follows:
- describe the purpose of the AI system, its scope, users and context;
- identify relevant stakeholders, including customers, employees, citizens and partners;
- identify potential financial, legal, reputational and social impacts, including privacy and discrimination risks;
- assess the likelihood and severity of those impacts, including in cases of misuse;
- define control measures such as human-in-the-loop oversight, automation limits, testing, logging and monitoring;
- document the results, assign responsibilities and define the conditions for reassessment.
It is important not to turn the assessment into a box-ticking exercise. The outcome should influence the product itself, for example by leading to changes in data, additional testing, human confirmation of decisions or restrictions on certain use cases.
Example: AI in Credit Scoring
A fintech service automatically assesses a loan application. Technical accuracy alone is not enough. It is necessary to check whether a particular group of customers systematically receives less favourable outcomes, whether a rejection can be explained, what happens when incorrect data is used, and who has the authority to review the algorithm’s decision.
For effective AI governance, this type of assessment should not be carried out only before deployment. There should be a designated process owner, ongoing monitoring, documented evidence of testing, and reassessment after changes to the model or data. In this context, ISO/IEC 42005 naturally complements an ISO/IEC 42001 management system..
Why Combine ISO/IEC 42005 and ISO 42001
For companies in Kazakhstan, Uzbekistan, Georgia and Kyrgyzstan, combining these two approaches helps them respond to customer enquiries with greater confidence, reduce uncertainty when launching AI products, and demonstrate that decisions are made according to established rules and procedures.
If AI processes confidential or personal data, its governance should logically be aligned with ISO/IEC 27001. These processes overlap in areas such as data management, access control and incident management.
ISO/IEC 42005 provides a tool for analysing impact, while ISO/IEC 42001 turns that analysis into a repeatable management process. This represents a shift from asking, “Does our model work?” to the more mature question, “Do we understand its impact, and are we able to manage it effectively?”
If an organisation already uses AI in significant business processes, a practical first step is to conduct a pilot assessment of one system, identify gaps, and use the findings as a basis for developing an artificial intelligence management system. System Management can help organisations across the CIS align assessment results with ISO/IEC 42001 requirements and prepare their processes for audit and certification.
